THREAT OPS › Threat News › Cisco Identity Services Engine Authorization Bypass Vulnerabilities
Cisco Identity Services Engine Authorization Bypass Vulnerabilities
<p>Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device.</p> <p>These vulnerabilities are due to the lack of server-side validation of <em>Administrator </em>permissions. An attacker could
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-20285cve
- CVE-2026-20286cve